Логотип exploitDog
bind:CVE-2020-18019
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-18019

Количество 2

Количество 2

nvd логотип

CVE-2020-18019

почти 5 лет назад

SQL Injection in Xinhu OA System v1.8.3 allows remote attackers to obtain sensitive information by injecting arbitrary commands into the "typeid" variable of the "createfolderAjax" function in the "mode_worcAction.php" component.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-cjm2-8vv6-ff66

больше 3 лет назад

SQL Injection in Xinhu OA System v1.8.3 allows remote attackers to obtain sensitive information by injecting arbitrary commands into the "typeid" variable of the "createfolderAjax" function in the "mode_worcAction.php" component.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-18019

SQL Injection in Xinhu OA System v1.8.3 allows remote attackers to obtain sensitive information by injecting arbitrary commands into the "typeid" variable of the "createfolderAjax" function in the "mode_worcAction.php" component.

CVSS3: 7.5
0%
Низкий
почти 5 лет назад
github логотип
GHSA-cjm2-8vv6-ff66

SQL Injection in Xinhu OA System v1.8.3 allows remote attackers to obtain sensitive information by injecting arbitrary commands into the "typeid" variable of the "createfolderAjax" function in the "mode_worcAction.php" component.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу